Vulnerability PYSEC-2026-3853
Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
19 days ago
September 10, 2026 at 09:44 AM UTC
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
0.1.0 - 5.4.6
0.1.0 - 5.4.6
Summary
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Details
Impact
Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.
Patches
Upgrade to 5.5.0.
Workarounds
Use an Authenticator that doesn't use a login form, such as OAuthenticator.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 month ago
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
0.1.0 - 5.4.6 GHSA-p43p-whwx-q52h
0.1.0 - 5.4.6 GHSA-p43p-whwx-q52h
High Risk
2 months ago
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
0.1.0 - 4.0.2 PYSEC-2026-1480
0.1.0 - 4.0.2 PYSEC-2026-1480
Medium Risk
2 months ago
Open Redirect vulnerability in jupyterhub and notebook
0.1.0 - 0.9.5 PYSEC-2026-647
0.1.0 - 0.9.5 PYSEC-2026-647
Medium Risk
4 months ago
No summary available
4.1.0 - 5.4.4 PYSEC-2026-2189
4.1.0 - 5.4.4 PYSEC-2026-2189
Medium Risk
4 months ago
JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
4.1.0 - 5.4.4 GHSA-m68r-v472-jgq9
4.1.0 - 5.4.4 GHSA-m68r-v472-jgq9
Impacted packages
Timeline
Published
19 days ago
September 10, 2026 at 09:44 AM UTC
Fixed (5.5.0)
3 months ago
June 10, 2026 at 09:12 PM UTC
Last Modified
2 hours ago
September 29, 2026 at 10:10 AM UTC